Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek
ID: 047d45b3-eb20-53e8-8fc4-5808f868595c
STIX ID: report--047d45b3-eb20-53e8-8fc4-5808f868595c
Feed Name: The Register (Security)
Threat Score
Wiz discovered a publicly accessible, unauthenticated ClickHouse instance tied to DeepSeek that exposed more than a million log entries containing plaintext chat history, API secrets, backend details, timestamps, and operational metadata. The database allowed arbitrary SQL via an HTTP /play endpoint, giving the potential for full control and privilege escalation; DeepSeek patched the issue after being informed, and regulators in Europe are investigating.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
